Privacy Policy
How OMRpro handles the data an institution puts into it, and what leaves the machines in
your exam hall.
Who this covers
OMRpro is sold to educational institutions. The institution is the owner of the exam and
student data it enters; we process that data on the institution's behalf so it can scan answer
sheets, calculate results and share them. Students and guardians do not hold accounts — their
information reaches us only because their institution entered it.
What stays on your own computers
The desktop application is offline-first, and this is the most important thing to understand
about it:
-
Scanned sheets are read on the machine that scanned them. The marks are
detected locally, and the image files stay in the folder on that PC. Unless your institution
switches on the cloud archive described below, the images never leave that PC.
-
While a scan session is open the application makes no network calls at all,
by design. Scanning works with the internet disconnected.
-
A local database on that PC holds the exam configuration, the answer key, the roll numbers
and names needed to label results, and the results themselves.
What is sent to us
When an operator chooses to sync a completed session, the following is transmitted:
- Scan session details — when it ran, which machine, how many sheets, how many were flagged.
- Per-sheet results — roll number, set code, the option selected for each question, the marks
awarded, and any manual correction an operator made.
- The exam's configuration and answer key, so results can be recalculated and displayed.
By default the sheet images are not part of this. What we receive is the
reading of the sheet, not the sheet.
Sheet image archive (only if your institution turns it on)
An institution can ask for its processed sheet images to be kept in the cloud, so that staff can
look at a sheet from the web portal. This is off unless it has been switched on for the
institution's account. When it is on:
-
After a scan session's results have synced, the desktop uploads the processed image of each
sheet (the scan with the detected marks drawn on it). Nothing is uploaded while a scan session
is open, and each desktop can also turn uploading off in its own settings.
-
The images are stored in Cloudflare R2, a cloud object store, in a private
bucket operated for OMRpro. They are not public: a sheet can only be opened by a signed-in
user of the same institution, through a link that expires after a few minutes.
-
Each image is kept for the retention period of the institution's plan,
counted from the exam date, and is then deleted automatically. Clearing an exam's results
deletes its images as well. The storage an institution uses counts toward its plan's storage
allowance.
Student information
-
The desktop keeps only what it needs to put a name against a scanned sheet: a
roll number and a name, per exam.
-
Fuller student records — date of birth, gender, mobile number, batch, guardian details —
exist only where an institution chooses to enter them in the web portal, and are used to
enrich results and, if the institution enables it, to send result messages.
-
Result SMS is opt-in per student. A student without an opt-in flag is not
messaged, and the dispatch screen states how many recipients are excluded for that reason.
-
A public result link, if an institution generates one, lets a student look up
their own result by roll number only. Names are never shown on that page,
and it lists no one else.
Accounts, machines and sign-in
-
For each user we store name, email address, role and sign-in history. Passwords are stored
hashed; we cannot read them.
-
Signing in to the desktop application happens in your browser. Your password is never typed
into the desktop app.
-
We record which machines an institution has activated — a machine name, an identifier
generated on that PC, the app and OS version, and when it last checked in — so an
administrator can see and revoke them. That identifier is generated locally and is not tied
to any hardware serial number.
-
Administrative actions are written to an audit log so an institution can see who changed
what.
Where data is held
Cloud data is stored in a database operated for OMRpro, and each institution's data is
separated by a tenant identifier applied to every record. Uploaded files — logos, photos,
support attachments and, where the archive is switched on, sheet images — are kept either on the
service's own server or in a private Cloudflare R2 bucket operated for OMRpro, under the same
separation. Staff access is limited to what is needed to support the service.
How long it is kept
Exam and result data is kept while the institution's subscription is active, so that past
results remain available. Archived sheet images are the exception: each is deleted when the
plan's retention period after its exam date has passed. Local data on a scanning PC stays there until the institution removes
it — uninstalling the desktop application does not by itself erase the local database.
A specific retention period, and what happens to data after a subscription ends, is still to be
settled and will be stated here.
Our public website
The public pages of this site — the home page, the download page, these policy pages and the
sign-in page — use Google Analytics to count visits and see which pages are read. Google receives
the page address, your browser and device type, an approximate location derived from your IP
address, and a cookie that recognises a returning browser. Nothing inside the signed-in
application is measured, so no exam, student or result data ever reaches it.
What we do not do
- We do not sell data, and we do not share it with advertisers.
- We do not use student data to train models.
- We do not view scanned sheet images — we never receive them.
Your institution's rights over its data
Results can be exported at any time from the portal (Excel and PDF). If an institution wants
data corrected or deleted, an administrator should contact us; because we act on the
institution's behalf, requests from individual students or guardians are directed to their
institution first.
Language
This policy is provided in English and Bengali. If the two versions disagree, the
English version governs.
বাংলা সংস্করণ দেখুন.
Contact
Questions about this policy or about your data:
support@omrpro.net.